AppSecNews

DAST

Dynamic Application Security Testing

Probe a running application from the outside, the way an attacker would.

34 tools profiled

How it differs Tests the running application from the outside, with no access to source. SAST never runs the app; IAST instruments it from the inside.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

8 tools match

  • Arachni

    Arachni Project (Tasos Laskos)

    DAST

    Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.

    Open source
    Established
  • Burp Suite

    PortSwigger

    DAST

    Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.

    Freemium
    Established Verified
  • Caido

    Caido Labs

    DAST

    Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.

    Not recorded
    Growing
  • DAST

    Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.

    Commercial
    Established
  • Arachni

    Arachni Project (Tasos Laskos)

    Ruby based web application security scanner with an integrated browser environment, driven from the command line or a self hosted web interface.

    Open source Established
    DAST
  • Burp Suite

    PortSwigger

    Intercepting proxy and testing toolkit that puts a human in the request path, with an automated scanner and an extension ecosystem around it.

    Freemium Established
    DAST
  • Caido

    Caido Labs

    Web security testing proxy built around a separate client and server, with a query language for filtering traffic and a plugin system for automation.

    Not recorded Growing
    DAST
  • Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.

    Commercial Established
    DAST
  • HCL AppScan

    HCLSoftware

    DAST

    Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.

    Commercial
    Established
  • DAST

    Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.

    Commercial
    Established
  • w3af

    Andres Riancho and contributors

    DAST

    Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.

    Open source
    Established
  • ZAP

    ZAP project, Software Security Project

    DAST

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source
    Established Verified
  • HCL AppScan

    HCLSoftware

    Long established enterprise application security suite whose dynamic scanner crawls and audits running applications with heavy scan configuration options.

    Commercial Established
    DAST
  • Black-box web application scanner from Syhunt's hybrid analysis suite, run from a desktop interface or scripted from the command line.

    Commercial Established
    DAST
  • w3af

    Andres Riancho and contributors

    Open source web application attack and audit framework built around crawl, audit, grep and attack plugins driven from a console or GUI.

    Open source Established
    DAST
  • ZAP

    ZAP project, Software Security Project

    Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.

    Open source Established
    DAST
Tick up to 4 tools above.